Dashboards & Visualizations

Dashboard reports not updating since upgrade to Splunk 6

pixelseventy2
Explorer

Hi. I've created a number of dashboards using Saved Searches, instead of inline queries. Since updating to Splunk 6, these aren't updating when the dashboard is refreshed. The panels with inline queries update normally. Do they need to be scheduled to update?

For example, I have a report which shows Administrator logons for the last 6 hours. I want this to update periodically. They are displayed in Chrome with an extension to rotate through the tabs every 60 seconds and refresh.

Should I just schedule these reports to run every 5 minutes or so? Or change them to inline queries.

Thanks.

0 Karma

melting
Splunk Employee
Splunk Employee

Yes, one of the advantages to using saved searches (reports) in dashboards is to have them run faster by using the latest run of that saved search.

So if you want results more frequently you can schedule that search to run more frequently. You could also set the dispatch.ttl to a smaller number so results will expire quicker.

0 Karma

pixelseventy2
Explorer

Unfortunately, I realised that because we're on Splunk Free I can't schedule reports, so I've had to change them all to inline queries.

Has the old "Saved Search" functionality been removed completely in favour of Reports? It was useful to be able to save common queries that I didn't necessarily want as a report, and access them from the menu drop down.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...